Signed ADO build Artifacts

Jennifer Olsen 1 Reputation point
2021-03-30T20:00:01.08+00:00

Our InfoSec team has asked us to show them how we are able to verify that the build artifacts deployed to a server target are the same build artifacts that were generated in our ADO pipelines, sent to Veracode (our code scanning service), approved in the ADO release process, and deployed through the ADO deployment agents.

The InfoSec team explains that ideally there would be a SHA hash on those artifacts that we could trace back through our process. Is this feasible with Azure DevOps out of the box? I cannot seem to find any Microsoft documentation regarding signed build artifacts that are created from within ADO. I have found that we could create a feed from another build service to pull the artifacts into ADO; however, we are using ADO pipelines to build our releases.

Community Center | Not monitored
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. tbgangav-MSFT 10,426 Reputation points Moderator
    2021-03-31T01:45:42.797+00:00

    Hi @Jennifer Olsen ,

    Azure DevOps is currently not supported in this Microsoft Q&A platform. You may ask Azure DevOps related questions in this developer community.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.